High severity7.7NVD Advisory· Published Jun 22, 2026· Updated Jul 10, 2026
CVE-2026-42129
CVE-2026-42129
Description
A user with Viewer permissions can use a path traversal in the Loki data source plugin to reach administrative Loki endpoints and read sensitive backend configuration and internal service information.
Affected products
2- cpe:2.3:a:grafana:loki_datasource:-:*:*:*:*:*:*:*
Patches
Vulnerability mechanics
References
1- grafana.com/security/security-advisories/cve-2026-42129nvdBroken Link
News mentions
0No linked articles in our index yet.